Skip to content

Secret disclosure when containing characters that become URI encoded

high severity CVE-2020-26226 published Nov 18, 2020 • updated Nov 18, 2020
Repository
@semantic-release semantic-release/semantic-release
Packages Affected versions Patched versions
semantic-release (npm) <= 17.2.2 17.2.3

Impact

Secrets that would normally be masked by semantic-release can be accidentally disclosed if they contain characters that become encoded when included in a URL.

Patches

Fixed in v17.2.3

Workarounds

Secrets that do not contain characters that become encoded when included in a URL are already masked properly.

References

Credits

@travi travi published the maintainer security advisory Nov 16, 2020
You can’t perform that action at this time.